Grandstream GWN7000 firmware version 1.0.9.4 and below allows authenticated remote users to modify the system's crontab via undocumented API. An attacker can use this functionality to execute arbitrary OS commands on the router.
References
Link | Resource |
---|---|
https://www.tenable.com/security/research/tra-2020-41 | Not Applicable |
https://www.tenable.com/cve/CVE-2020-5756 | Exploit Third Party Advisory |
https://www.tenable.com/security/research/tra-2020-41 | Not Applicable |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 05:34
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.tenable.com/security/research/tra-2020-41 - Not Applicable |
Information
Published : 2020-07-17 21:15
Updated : 2024-11-21 05:34
NVD link : CVE-2020-5756
Mitre link : CVE-2020-5756
CVE.ORG link : CVE-2020-5756
JSON object : View
Products Affected
grandstream
- gwn7000_firmware
- gwn7000